网络安全日报 2021年10月27日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Adobe 修补了 14 种软件产品中存在的安全漏洞 https://www.securityweek.com/adobe-patches-gaping-security-flaws-14-software-products 2、ZDI 宣布 Pwn2Own Miami 竞赛的目标和奖品 https://www.securityweek.com/targets-and-prizes-announced-2022-ics-themed-pwn2own 3、FBI发布警报称Ranzy Locker 勒索软件已攻击了数十家美国公司 https://securityaffairs.co/wordpress/123801/cyber-crime/ranzy-locker-ransomware.html 4、UltimaSMS 订阅欺诈活动针对数百万 Android 用户 https://securityaffairs.co/wordpress/123795/malware/ultimasms-massive-fraud-campaign.html 5、研究人员发现APT 组织Lazarus 转向 IT 供应链攻击 https://threatpost.com/lazarus-apt-it-supply-chain/175772/ 6、伊朗各地加油站遭受网络攻击 https://therecord.media/suspected-cyberattack-temporarily-disrupts-gas-stations-across-iran 7、 EntroLink VPN 设备中的零日漏洞被勒索软件利用 https://therecord.media/ransomware-gangs-are-abusing-a-zero-day-in-entrolink-vpn-appliances 8、英国超市特易购的网站和应用程序遭受网络攻击 https://www.bbc.com/news/business-59027423 9、Gummy Browsers攻击可收集用户的浏览器指纹信息 https://cyware.com/news/gummy-browsers-attack-lets-hackers-spoof-your-digital-identity-eaf11598 10、Magnitude EK 利用基于 Chromium 的浏览器漏洞 https://cyware.com/news/magnitude-ek-exploiting-chromium-based-browser-flaws-93e9aec3
网络安全日报 2021年10月26日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、研究人员发现Polygon 中的严重漏洞获得 200 万美元奖励 https://www.securityweek.com/researcher-earns-2-million-critical-vulnerability-polygon 2、微软警告称与俄有关的APT组织持续进行IT供应链攻击 https://securityaffairs.co/wordpress/123754/apt/nobelium-apt-it-supply-chain.html 3、一个未知勒索团伙利用 BillQuick 中的SQL注入进行攻击 https://securityaffairs.co/wordpress/123783/cyber-crime/ransomware-gang-billquick-web-suite-bug.html 4、Discourse 存在严重远程代码执行漏洞 https://securityaffairs.co/wordpress/123775/hacking/discourse-rce.html 5、研究人员发现爱立信 OSS-RC 组件中两个严重漏洞 https://securityaffairs.co/wordpress/123764/security/ericsson-oss-rc-flaws.html 6、Emsisoft 发布了BlackMatter 勒索软件解密器 https://securityaffairs.co/wordpress/123736/security/blackmatter-decryptor-pat-victims.html 7、韩国电信公司KT遭受DDoS攻击导致网络瘫痪 https://www.zdnet.com/article/large-ddos-attack-shuts-down-south-korean-telcos-nationwide-network/ 8、Groove勒索软件呼吁同行联合打击美国政府 https://securityaffairs.co/wordpress/123684/malware/groove-ransomware-gang-call-to-action.html 9、报告称东京奥运会期间遭4.5 亿次网络攻击 https://www.zdnet.com/article/nearly-450-million-cyberattacks-attempted-on-japan-olympics-infrastructure-ntt 10、 微软发现钓鱼工具TodayZoo 被广泛用于证书窃取攻击 https://securityaffairs.co/wordpress/123729/cyber-crime/todayzoo-phishing-kit.html
网络安全日报 2021年10月25日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、npm包UAParser.js遭供应链攻击被植入恶意挖矿软件 https://www.securityweek.com/critical-severity-warning-malware-embedded-popular-javascript-library 2、Facebook 推出用于查找 SSRF 漏洞的新工具 https://www.securityweek.com/facebook-introduces-new-tool-finding-ssrf-vulnerabilities 3、北约发布首个人工智能战略 https://securityaffairs.co/wordpress/123715/security/nato-strategy-artificial-intelligence.html 4、有人在黑客论坛出售 5000 万莫斯科司机的数据 https://securityaffairs.co/wordpress/123711/data-breach/moscow-drivers-data-leak.html 5、思科修复了 SD-WAN 中的操作系统命令注入漏洞 https://securityaffairs.co/wordpress/123704/security/cisco-sd-wan-flaw.html 6、FIN7 黑客组织创建虚假的网络安全公司招人进行勒索攻击 https://securityaffairs.co/wordpress/123673/cyber-crime/fin7-fake-cybersecurity-firm.html 7、美国执法部门入侵并破坏了 REvil 勒索团伙的服务器 https://www.securityweek.com/revil-ransomware-gang-hit-law-enforcement-hack-back-operation 8、谷歌推出 Android Enterprise 漏洞赏金计划 https://www.bleepingcomputer.com/news/security/google-launches-android-enterprise-bug-bounty-program/ 9、工业公司AUVESY的Versiondog数据管理产品存在多个严重漏洞 https://www.securityweek.com/critical-vulnerabilities-found-auvesy-product-used-major-industrial-firms 10、TodayZoo网络钓鱼活动仿冒Microsoft 365登录页面 https://www.zdnet.com/article/this-frankensteins-monster-of-a-phishing-campaign-is-after-your-passwords/
网络安全日报 2021年10月22日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、FiveSys Rootkit 滥用微软发布的数字签名 https://www.securityweek.com/fivesys-rootkit-abuses-microsoft-issued-digital-signature 2、研究人员发现WinRAR 中的远程代码执行漏洞 https://securityaffairs.co/wordpress/123652/hacking/winrar-trial-flaw.html 3、美国将限制网安产品出口到俄罗斯和中国 https://www.securityweek.com/us-curb-hacking-tool-exports-russia-china 4、技嘉被 AvosLocker 勒索软件攻击 https://threatpost.com/gigabyte-avoslocker-ransomware-gang/175642/ 5、黑客窃取浏览器Cookie以劫持知名YouTube创作者帐户 https://thehackernews.com/2021/10/hackers-stealing-browser-cookies-to.html 6、新的 Gummy 攻击可以捕获数字指纹并发起浏览器欺骗攻击 https://www.bleepingcomputer.com/news/security/new-gummy-browsers-attack-lets-hackers-spoof-tracking-profiles/ 7、Evil Corp 推出名为 Macaw Locker 的新型勒索软件 https://securityaffairs.co/wordpress/123661/cyber-crime/evil-corp-macaw-locker.html 8、Chrome 95 将FTP代码从代码库中删除 https://www.theregister.com/2021/10/20/ftp_chrome_95/ 9、Slack存在XSLeak漏洞可以对用户进行去匿名化 https://portswigger.net/daily-swig/slack-contains-an-xsleak-vulnerability-that-de-anonymizes-users 10、APT组织lone wolf正在积极利用一个古老的微软Office漏洞 https://threatpost.com/apt-commodity-rats-microsoft-bug/175601/
网络安全日报 2021年10月21日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、研究人员使用新的“SmashEx”CPU 攻击技术破解 Intel SGX https://thehackernews.com/2021/10/researchers-break-intel-sgx-with-new.html 2、微软警告影响 Surface Pro 3 设备的新安全漏洞 https://thehackernews.com/2021/10/microsoft-warns-of-new-security-flaw.html 3、宏碁已确认除印度服务器外黑客还入侵了台湾部分服务器 https://www.securityweek.com/acer-confirms-breach-servers-taiwan 4、谷歌发布Chrome 95 ,修复了 19 个漏洞 https://www.securityweek.com/google-patches-19-vulnerabilities-chrome-95-browser-refresh 5、PurpleFox 僵尸网络利用WebSockets进行C2通信 https://securityaffairs.co/wordpress/123623/malware/purplefox-botnet-websockets.html 6、"网络军火商" Zerodium 正在寻找NordVPN等客户端零日漏洞 https://securityaffairs.co/wordpress/123581/hacking/zerodium-expressvpn-nordvpn-surfshark.html 7、Oracle 10 月重要补丁更新包含 419 个安全补丁 https://www.securityweek.com/oracles-october-2021-cpu-includes-419-security-patches 8、macOS Gatekeeper 绕过漏洞正在被广泛利用 https://cyware.com/news/poc-exploit-that-bypass-macos-security-is-out-and-being-exploited-1379c82f 9、TA505团伙通过电子邮件传播FlawedGrace新变种 https://threatpost.com/ta505-retooled-flawedgrace-rat/175559/ 10、FBI警告用于窃取财务和个人数据的虚假政府网站 https://www.bleepingcomputer.com/news/security/fbi-warns-of-fake-govt-sites-used-to-steal-financial-personal-data/
网络安全日报 2021年10月20日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、研究人员披露了Squirrel Engine中的严重漏洞 https://thehackernews.com/2021/10/squirrel-engine-bug-could-let-attackers.html 2、FBI、CISA和NSA联合发布 BlackMatter 勒索软件紧急警告 https://securityaffairs.co/wordpress/123549/cyber-crime/blackmatter-ransomware-joint-advisory.html 3、赛门铁克发现新的APT组织Harvester针对南亚电信提供商和IT公司 https://securityaffairs.co/wordpress/123559/apt/harvester-targets-telcos.html 4、研究人员发现新的 Karma 勒索软件可能是Nemty的变体 https://securityaffairs.co/wordpress/123568/malware/karma-ransomware-nemty-similarities.html 5、Node.js修复了两个HTTP请求走私漏洞 https://portswigger.net/daily-swig/node-js-was-vulnerable-to-a-novel-http-request-smuggling-technique 6、反电信网络诈骗法(草案)首次提请审议 https://www.cnbeta.com/articles/tech/1192495.htm 7、美国将价值52亿美元的比特币交易与勒索软件挂钩 https://www.bleepingcomputer.com/news/security/us-links-52-billion-worth-of-bitcoin-transactions-to-ransomware/ 8、Thingiverse数据泄漏影响228000个订户 https://www.databreachtoday.com/thingiverse-data-leak-affects-228000-subscribers-a-17729 9、中兴通讯LTE路由器中发现多个漏洞 https://blog.talosintelligence.com/2021/10/vuln-spotlight-.html 10、黑客入侵了阿根廷政府的 IT 网络并窃取了该国所有ID数据库 https://therecord.media/hacker-steals-government-id-database-for-argentinas-entire-population
网络安全日报 2021年10月19日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、安全研究人员发布BlackByte勒索软件解密器 https://www.securityweek.com/free-decryptor-released-blackbyte-ransomware 2、密码审计和恢复工具 L0phtCrack 已开源发布 https://www.securityweek.com/password-auditing-tool-l0phtcrack-released-open-source 3、Sinclair 广播集团遭勒索攻击,旗下电视台停播 https://www.securityweek.com/sinclair-hit-ransomware-attack-tv-stations-disrupted 4、TeamTNT 在 Docker Hub 上部署恶意 Docker 镜像 https://securityaffairs.co/wordpress/123535/cyber-crime/teamtnt-docker-attack.html 5、微软敦促系统管理员修补 PowerShell 漏洞以修复 WDAC 绕过 https://www.bleepingcomputer.com/news/microsoft/microsoft-asks-admins-to-patch-powershell-to-fix-wdac-bypass 6、在 Tor 站点遭到入侵后,REvil 勒索软件团伙再次停止运营 https://thehackernews.com/2021/10/revil-ransomware-gang-goes-underground.html 7、Windows、iOS、Chrome等多种系统和应用在天府杯上被攻破 https://thehackernews.com/2021/10/windows-10-linux-ios-chrome-and-many.html 8、Lyceum组织使用C++编写的新恶意软件发起攻击 https://securelist.com/lyceum-group-reborn/104586/ 9、Minecraft成为受恶意软件感染最多的游戏 https://www.hackread.com/minecraft-most-malware-infected-game/ 10、事件监控解决方案Prometheus容易暴露敏感数据 https://www.securityweek.com/many-prometheus-endpoints-expose-sensitive-data
网络安全日报 2021年10月18日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、Trickbot攻击者扩大恶意软件分发渠道 https://thehackernews.com/2021/10/attackers-behind-trickbot-expanding.html 2、勒索软件攻击了美国 3 个供水设施的 SCADA 系统 https://www.securityweek.com/ransomware-hit-scada-systems-3-water-facilities-us 3、研究人员披露了影响所有 AMD CPU 的新侧信道攻击 https://www.securityweek.com/researchers-disclose-new-side-channel-attacks-affecting-all-amd-cpus 4、iPhone 13 iOS 15 在天府杯中被破解 https://securityaffairs.co/wordpress/123476/hacking/tianfu-cup-2021-hacking-contest.html 5、厄瓜多尔最大银行 Banco Pichincha遭黑客攻击后服务中断 https://securityaffairs.co/wordpress/123465/cyber-crime/ecuadors-banco-pichincha-cyberattack.html 6、埃森哲披露 LockBit 勒索软件攻击后的数据泄露 https://securityaffairs.co/wordpress/123422/data-breach/accenture-data-breach-lockbit-ransomware.html 7、Juniper 发布补丁修补70多个漏洞 https://www.securityweek.com/juniper-networks-patches-over-70-vulnerabilities 8、与俄罗斯有关的 TA505 组织新的邮件钓鱼活动针对金融机构 https://securityaffairs.co/wordpress/123441/breaking-news/ta505-mirrorblast-malspam-campaign.html 9、MyKings僵尸网络利用受感染的计算机网络挖矿 https://www.zdnet.com/article/this-relentless-malware-botnet-has-made-millions-with-a-surprisingly-simple-trick/ 10、Twitch表示数据泄露事件只影响了一小部分用户 https://www.securityweek.com/twitch-says-hack-impacted-small-fraction-users
网络安全日报 2021年10月15日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、WhatsApp 推出端到端加密聊天备份 https://securityaffairs.co/wordpress/123389/security/whatsapp-made-available-end-to-end-encrypted-chat-backups.html 2、2020 年以来至少有 130 个不同的勒索软件家族处于活动状态 https://securityaffairs.co/wordpress/123376/malware/virustotal-ransomware-report.html 3、以色列Hillel Yaffe 医疗中心遭到重大勒索软件攻击 https://securityaffairs.co/wordpress/123350/hacking/israeli-hospital-ransomware-attack.html 4、新型勒索软件"Yanluowang"针对大型企业进行攻击 https://securityaffairs.co/wordpress/123328/malware/yanluowang-ransomware-targeted-attacks.html 5、Brizy WordPress 插件漏洞 可导致站点被接管 https://threatpost.com/brizy-wordpress-plugin-exploit-site-takeovers/175463/ 6、Verizon 的 Visible 用户遭遇凭证填充攻击 https://threatpost.com/verizon-visible-wireless-credential-stuffing/175483/ 7、Linphone 和 MicroSIP 软电话披露的严重远程攻击漏洞 https://thehackernews.com/2021/10/critical-remote-hacking-flaws-disclosed.html 8、研究人员发现广告拦截插件AllBlock会在后台注入广告 https://www.theregister.com/2021/10/14/ad_blocker_injects_bad_ads/ 9、网络钓鱼攻击者使用电报机器人窃取OTP代码 https://cyware.com/news/telegram-bots-used-in-latest-campaigns-to-steal-otps-bd401a98 10、研究人员披露了ITG23网络犯罪团伙的活动 https://securityintelligence.com/posts/trickbot-gang-doubles-down-enterprise-infection/
网络安全日报 2021年10月14日
免责声明:以下内容原文来自互联网的公共方式,仅用于有限分享,译文内容不代表蚁景网安实验室观点,因此第三方对以下内容进行分享、传播等行为,以及所带来的一切后果与译者和蚁景网安实验室无关。以下内容亦不得用于任何商业目的,若产生法律责任,译者与蚁景网安实验室一律不予承担。 1、APT28 发起针对 Gmail 用户的鱼叉式网络钓鱼活动 https://cyware.com/news/apt28-launches-spearphishing-campaign-against-gmail-users-google-warns-84b73646 2、Apache 服务器最近修复的两个漏洞正被积极利用 https://cyware.com/news/two-flaws-in-apache-servers-are-under-attack-d493d3f9 3、厄瓜多尔最大私人银行皮钦查银行遭受大规模网络攻击 https://www.bleepingcomputer.com/news/security/cyberattack-shuts-down-ecuadors-largest-bank-banco-pichincha/ 4、谷歌成立网络安全行动小组 https://www.infosecurity-magazine.com/news/google-creates-cybersecurity/ 5、由于安全配置错误,巴西电商公司Hariexpress泄露了超过 17 亿条记录 https://www.infosecurity-magazine.com/news/ecommerce-player-leaks-billion/ 6、Nagios XI 更新以解决三个安全漏洞 https://portswigger.net/daily-swig/nagios-xi-updated-to-address-trio-of-security-vulnerabilities 7、OpenSea 的严重漏洞可让黑客从钱包中窃取加密货币 https://thehackernews.com/2021/10/critical-flaw-in-opensea-could-have-let.html 8、攻击者使用数学符号来逃避反网络钓鱼检测 https://securityaffairs.co/wordpress/123297/hacking/anti-phishing-technique.html 9、研究人员披露了一个新的SnapMC黑客组织 https://therecord.media/new-snapmc-group-extorts-companies-after-short-30-minute-hacks 10、Windows 零日漏洞被积极利用 https://threatpost.com/windows-zero-day-exploited-espionage/175432/